Lucene search

K
cveIntelCVE-2016-8031
HistoryMar 28, 2017 - 3:59 p.m.

CVE-2016-8031

2017-03-2815:59:00
CWE-264
intel
web.nvd.nist.gov
33
intel
ave
5200
5800
vulnerability
security
bypass
local users
crafted input file
nvd

CVSS2

4.4

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

CVSS3

7.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

AI Score

6.9

Confidence

High

EPSS

0

Percentile

5.1%

Software Integrity Attacks vulnerability in Intel Security Anti-Virus Engine (AVE) 5200 through 5800 allows local users to bypass local security protection via a crafted input file.

Affected configurations

Nvd
Node
mcafeeanti-malware_scan_engineMatch5200aix
OR
mcafeeanti-malware_scan_engineMatch5200freebsd
OR
mcafeeanti-malware_scan_engineMatch5200hp-ux
OR
mcafeeanti-malware_scan_engineMatch5200linux
OR
mcafeeanti-malware_scan_engineMatch5200solaris
OR
mcafeeanti-malware_scan_engineMatch5200windows
OR
mcafeeanti-malware_scan_engineMatch5300aix
OR
mcafeeanti-malware_scan_engineMatch5300freebsd
OR
mcafeeanti-malware_scan_engineMatch5300hp-ux
OR
mcafeeanti-malware_scan_engineMatch5300linux
OR
mcafeeanti-malware_scan_engineMatch5300solaris
OR
mcafeeanti-malware_scan_engineMatch5300windows
OR
mcafeeanti-malware_scan_engineMatch5400aix
OR
mcafeeanti-malware_scan_engineMatch5400freebsd
OR
mcafeeanti-malware_scan_engineMatch5400hp-ux
OR
mcafeeanti-malware_scan_engineMatch5400linux
OR
mcafeeanti-malware_scan_engineMatch5400solaris
OR
mcafeeanti-malware_scan_engineMatch5400windows
OR
mcafeeanti-malware_scan_engineMatch5500aix
OR
mcafeeanti-malware_scan_engineMatch5500freebsd
OR
mcafeeanti-malware_scan_engineMatch5500hp-ux
OR
mcafeeanti-malware_scan_engineMatch5500linux
OR
mcafeeanti-malware_scan_engineMatch5500solaris
OR
mcafeeanti-malware_scan_engineMatch5500windows
OR
mcafeeanti-malware_scan_engineMatch5600aix
OR
mcafeeanti-malware_scan_engineMatch5600freebsd
OR
mcafeeanti-malware_scan_engineMatch5600hp-ux
OR
mcafeeanti-malware_scan_engineMatch5600linux
OR
mcafeeanti-malware_scan_engineMatch5600solaris
OR
mcafeeanti-malware_scan_engineMatch5600windows
OR
mcafeeanti-malware_scan_engineMatch5700aix
OR
mcafeeanti-malware_scan_engineMatch5700freebsd
OR
mcafeeanti-malware_scan_engineMatch5700hp-ux
OR
mcafeeanti-malware_scan_engineMatch5700linux
OR
mcafeeanti-malware_scan_engineMatch5700solaris
OR
mcafeeanti-malware_scan_engineMatch5700windows
OR
mcafeeanti-malware_scan_engineMatch5800aix
OR
mcafeeanti-malware_scan_engineMatch5800freebsd
OR
mcafeeanti-malware_scan_engineMatch5800hp-ux
OR
mcafeeanti-malware_scan_engineMatch5800linux
OR
mcafeeanti-malware_scan_engineMatch5800solaris
OR
mcafeeanti-malware_scan_engineMatch5800windows
VendorProductVersionCPE
mcafeeanti-malware_scan_engine5200cpe:2.3:a:mcafee:anti-malware_scan_engine:5200:*:*:*:*:aix:*:*
mcafeeanti-malware_scan_engine5200cpe:2.3:a:mcafee:anti-malware_scan_engine:5200:*:*:*:*:freebsd:*:*
mcafeeanti-malware_scan_engine5200cpe:2.3:a:mcafee:anti-malware_scan_engine:5200:*:*:*:*:hp-ux:*:*
mcafeeanti-malware_scan_engine5200cpe:2.3:a:mcafee:anti-malware_scan_engine:5200:*:*:*:*:linux:*:*
mcafeeanti-malware_scan_engine5200cpe:2.3:a:mcafee:anti-malware_scan_engine:5200:*:*:*:*:solaris:*:*
mcafeeanti-malware_scan_engine5200cpe:2.3:a:mcafee:anti-malware_scan_engine:5200:*:*:*:*:windows:*:*
mcafeeanti-malware_scan_engine5300cpe:2.3:a:mcafee:anti-malware_scan_engine:5300:*:*:*:*:aix:*:*
mcafeeanti-malware_scan_engine5300cpe:2.3:a:mcafee:anti-malware_scan_engine:5300:*:*:*:*:freebsd:*:*
mcafeeanti-malware_scan_engine5300cpe:2.3:a:mcafee:anti-malware_scan_engine:5300:*:*:*:*:hp-ux:*:*
mcafeeanti-malware_scan_engine5300cpe:2.3:a:mcafee:anti-malware_scan_engine:5300:*:*:*:*:linux:*:*
Rows per page:
1-10 of 421

CNA Affected

[
  {
    "product": "Anti-Virus Engine (AVE)",
    "vendor": "Intel",
    "versions": [
      {
        "status": "affected",
        "version": "5200 through 5800"
      }
    ]
  }
]

CVSS2

4.4

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

CVSS3

7.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

AI Score

6.9

Confidence

High

EPSS

0

Percentile

5.1%

Related for CVE-2016-8031